<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why does Linux Auditd App filter out root for the user lookup? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-Linux-Auditd-App-filter-out-root-for-the-user-lookup/m-p/531796#M89451</link>
    <description>&lt;P&gt;The root user is the only truly universal user on any Linux machine so it's not in the learnt identities but the static identities lookup (&lt;A href="https://github.com/doksu/splunk_auditd/blob/master/TA-linux_auditd/lookups/posix_identities.csv" target="_blank"&gt;https://github.com/doksu/splunk_auditd/blob/master/TA-linux_auditd/lookups/posix_identities.csv&lt;/A&gt;), and they get merged together automatically. Best check your static identities lookup to ensure it has root in it.&lt;/P&gt;</description>
    <pubDate>Thu, 03 Dec 2020 03:29:31 GMT</pubDate>
    <dc:creator>doksu</dc:creator>
    <dc:date>2020-12-03T03:29:31Z</dc:date>
    <item>
      <title>Why does Linux Auditd App filter out root for the user lookup?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-Linux-Auditd-App-filter-out-root-for-the-user-lookup/m-p/531733#M89438</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P data-unlink="true"&gt;I have been using the Linux Auditd app, which has been great, but I noticed that the&amp;nbsp;learnt_posix_identities&amp;nbsp; lookup filters out the root user.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;[|inputlookup auditd_indices] [|inputlookup auditd_sourcetypes] type="USER_START" acct=* NOT acct=root NOT auid=0 terminal=/dev/tty* OR NOT addr=? | dedup auid | table auid acct | rename auid as _key | rename acct as user | outputlookup append=true learnt_posix_identities&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A lot of my syscalls are coming from root and the dashboards display unknown user. I could just manually edit the KV Store to add root, however I wanted to understand why this filter was here to make sure I don't break something.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2020 16:17:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-Linux-Auditd-App-filter-out-root-for-the-user-lookup/m-p/531733#M89438</guid>
      <dc:creator>dconnett_splunk</dc:creator>
      <dc:date>2020-12-02T16:17:36Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Linux Auditd App filter out root for the user lookup?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-Linux-Auditd-App-filter-out-root-for-the-user-lookup/m-p/531796#M89451</link>
      <description>&lt;P&gt;The root user is the only truly universal user on any Linux machine so it's not in the learnt identities but the static identities lookup (&lt;A href="https://github.com/doksu/splunk_auditd/blob/master/TA-linux_auditd/lookups/posix_identities.csv" target="_blank"&gt;https://github.com/doksu/splunk_auditd/blob/master/TA-linux_auditd/lookups/posix_identities.csv&lt;/A&gt;), and they get merged together automatically. Best check your static identities lookup to ensure it has root in it.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2020 03:29:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-Linux-Auditd-App-filter-out-root-for-the-user-lookup/m-p/531796#M89451</guid>
      <dc:creator>doksu</dc:creator>
      <dc:date>2020-12-03T03:29:31Z</dc:date>
    </item>
  </channel>
</rss>

